ArgusLeaf

Partners

Companies that keep ArgusLeaf running.

ArgusLeaf runs on volunteer infrastructure. Hosting companies that operate on networks where phishing is an active problem can partner with us: they provide server resources, and in return they get direct visibility into phishing activity on their own ASN — domains their resolvers are serving, threats their customers are hitting.

This isn't a commercial relationship. There are no SLAs, no paid tiers, no priority queue. It's an exchange between people who take phishing seriously.

What you get

What the partnership includes — and what it doesn't.

Partnership is defined by what we can actually deliver as a volunteer-run project. We set clear boundaries up front so nobody's expectations are misaligned.

What we offer What we can't promise
"Infrastructure partner" credit on this page SLA or uptime guarantees
API access to phishing threats on your ASN / CIDR ranges Real-time alerting (API is pull-based)
RPZ (DNS blocklist) feed for your resolvers False-positive rate guarantees
DNS telemetry ingestion — your resolvers feed us, we score the domains Dedicated support channel or response time
Equal standing — no tiered hierarchy between partners Cash payments or revenue share

DNS telemetry

Your resolver logs can detect phishing faster.

Partner companies can run our open-source agent on their resolver nodes. The agent reads unbound, BIND9, or Windows DNS query logs, batches domains every five minutes, and sends them to ArgusLeaf's pipeline. We score them — the result goes back through the partner's threat API and RPZ feed.

No raw logs leave your network. The agent sends only resolved domain names (no client IPs, no query metadata). You control the deployment and can stop it at any time.

The agent is a single static Go binary — no runtime dependencies, no telemetry of its own.

View agent source

Become a partner

Five steps to partnership.

  1. Send an introduction

    Write to [email protected] with your company name, ASN, and a brief note on what you'd like to contribute (server, CIDR visibility, both).

  2. Short technical call

    We discuss your network footprint, what data the API would return, and how the DNS agent fits your resolver stack. No sales, no deck — just a technical conversation.

  3. Infrastructure setup

    If you're contributing a server: we deploy an ArgusLeaf worker via Docker. If you're contributing DNS telemetry: we install the agent and walk through the log path together.

  4. API key issuance

    We generate a Bearer key scoped to your ASN and CIDR ranges. The key unlocks GET /api/v1/partner/threats and GET /api/v1/partner/rpz-feed.

  5. Credit and ongoing access

    Your company appears on this page. The relationship continues as long as both sides find it useful — no contract, no lock-in.

Ready to start a conversation? Send a short note to [email protected] — we'll get back within a few days.